Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-41972

CVSS 5.4 · Medium EPSS 0.02% · P4

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProductVersion RangeStatus
HuaweiHarmonyOS6.1.0affected
6.0.0affected
5.1.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-41972

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
HuaweiHarmonyOS 6.1.0 -

II. Public POCs for CVE-2026-41972

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-41972

登录查看更多情报信息。

Vendor Advisories for CVE-2026-41972 (1)

Same Patch Batch · Huawei · 2026-06-09 · 15 CVEs total

CVE-2026-419766.6 MEDIUM音频框架权限控制漏洞
CVE-2026-419826.4 MEDIUMIPC模块竞态条件漏洞影响可用性
CVE-2026-419756.3 MEDIUM华为网络管理系统网络管理模块权限管理漏洞
CVE-2026-419735.9 MEDIUMAndroid呼叫组件权限控制漏洞
CVE-2026-419805.5 MEDIUM文件预览模块权限控制漏洞
CVE-2026-419795.5 MEDIUMXX软件打印模块权限控制漏洞
CVE-2026-419815.3 MEDIUMIPC模块越界写漏洞影响可用性
CVE-2026-419845.2 MEDIUM软件包管理服务UAF漏洞
CVE-2026-419855.1 MEDIUM软件包管理模块UAF漏洞
CVE-2026-419775.0 MEDIUMlog服务拒绝服务漏洞
CVE-2026-419784.4 MEDIUMclone模块权限控制漏洞
CVE-2026-419834.3 MEDIUM浏览器内核DoS漏洞
CVE-2026-419743.6 LOWService Notification权限控制漏洞
CVE-2026-419862.4 LOW文件系统逻辑绕过漏洞影响可用性

IV. Related Vulnerabilities

V. Comments for CVE-2026-41972

No comments yet


Leave a comment